PT-2002-1138 · Sgi · Irix
Published
2002-03-28
·
Updated
2008-09-05
·
CVE-2002-0040
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
SGI IRIX versions 6.5.11 through 6.5.15f
Description
The issue allows local users to cause privileged applications to dump core via the
HOSTALIASES environment variable, potentially enabling them to gain privileges.Recommendations
For SGI IRIX versions 6.5.11 through 6.5.15f, consider restricting access to the
HOSTALIASES environment variable to prevent exploitation. As a temporary workaround, limit the ability of local users to manipulate this variable until a fix is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Irix